Logo
npm

@hrmony/app-gateway-templates@0.0.51

Vulnerability report · Last retrieved from osv.dev September 29, 2026 at 8:10 PM UTC

Malicious

OSV ID

MAL-2026-17251

Ecosystem

npm

Summary

On require/import of @hrmony/app-gateway-templates, index.js (the package main) executes an exfiltration routine against a hardcoded attacker endpoint at https://hrnmn.dd.h4x.tv/save_instance_info_from_pkge_hrmony_app-gateway-templates. The routine performs an AWS IMDSv2 token PUT against 169.254.169.254, then uses that token to read instance identity, IAM role security-credentials (temporary AWS access key, secret key, and session token), and network metadata. It also enumerates process.env in full and recursively reads /var/run/secrets/, which on Kubernetes pods contains mounted service-account tokens and application secrets. All collected data is POSTed to the same attacker endpoint. The package name is a one-character drop from harmony and declares a runtime dependency on @hrmony/kit-5 in the same typosquat scope, so installing this package also pulls additional attacker-controlled code under the same scope.

Source: amazon-inspector (c7d3f05113dd7daa9fac2da8187afecc751fafcf96449e7f4eb4a5d9a4878844)

Protect your entire dependency tree

Scan your lock files automatically on every PR. Block malicious packages before they reach production.